Cybersecurity Act, 2020 (Act 1038)
gh-cyber-2020 · Act
The Cybersecurity Act, 2020 (Act 1038) is Ghana's principal cybersecurity and cyber-governance statute, assented to on 29 December 2020. It establishes the Cyber Security Authority (CSA) and provides the institutional and regulatory framework for regulating cybersecurity activities, protecting critical information infrastructure (CII), licensing cybersecurity service providers and professionals, responding to cybersecurity incidents (including through a national CERT), and protecting children online. While many of Ghana's general computer-misuse offences (unauthorised access, interception, computer fraud) continue to derive from the Electronic Transactions Act, 2008 (Act 772), the Cybersecurity Act is the modern centrepiece of Ghana's cybercrime and cybersecurity regime and contains its own offence and enforcement provisions. The Act provides for the identification, designation and protection of critical information infrastructure across vital sectors, requiring owners to comply with security directives and report incidents, and empowers the CSA to audit and investigate. It contains offences relating to unauthorised acts affecting CII and protected systems, the provision of unlicensed cybersecurity services, and obstruction of authorised officers. A dedicated set of provisions addresses the protection of children online, criminalising the production and distribution of child sexual abuse material and related conduct. The Act also addresses harmful or false digital content and unauthorised interference with data. On procedure and enforcement, the Act creates investigatory powers exercisable by authorised officers, including powers to enter premises, access and seize computers and data, and require the production of information, subject to safeguards; it provides for emergency measures to respond to cybersecurity threats and for the issuing of directives to CII owners. It establishes mechanisms for cooperation with foreign agencies and international bodies on cybersecurity and cybercrime matters. The Act is supported by subsidiary instruments, including directives and regulations issued by the CSA. Institutionally, the Cyber Security Authority is the lead regulator and enforcement body, responsible for licensing, CII protection, incident response, accreditation of cybersecurity professionals, and public awareness. The Act's data-interference and child-protection provisions give it overlaps with data-protection and digital-rights considerations, and it operates alongside the Data Protection Act, 2012 (Act 843).
- Establishes the Cyber Security Authority (CSA) as the lead regulator for cybersecurity, incident response and enforcement.
- Provides for the identification, designation, protection and audit of critical information infrastructure (CII), with security and incident-reporting duties on owners.
- Creates offences relating to unauthorised acts affecting CII/protected systems, unlicensed provision of cybersecurity services, and obstruction of authorised officers.
- Contains dedicated child online protection provisions criminalising child sexual abuse material and related conduct.
- Addresses harmful or false digital content and unauthorised interference with data.
- Grants authorised officers powers of entry, access, seizure and production of information, and provides for emergency response directives.
- Provides for licensing/accreditation of cybersecurity service providers and professionals and for international cooperation (general computer-misuse offences also derive from the Electronic Transactions Act, 2008 (Act 772)).